Description
Versions less than 0.0.6 of the Node.js stringstream module are vulnerable to an out-of-bounds read because of allocation of uninitialized buffers when a number is passed in the input stream (when using Node.js 4.x).
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:HExploitability: 2.2 | Impact: 4.2Attack Vector: Network
Complexity: High
Privileges: None
User Interaction: None
Scope: Unchanged
Confidentiality: Low
Integrity: None
Availability: High
Affected Packages3 packages
🔴Vulnerability Details
4CVEListCVE-2018-21270: Versions less than 0↗2020-12-03 ▶ OSVCVE-2018-21270: Versions less than 0↗2020-12-03 ▶ GHSAOut-of-bounds Read in stringstream↗2019-06-20 ▶ OSVOut-of-bounds Read in stringstream↗2019-06-20 ▶ 📋Vendor Advisories
2Red Hatnodejs-stringstream: out-of-bounds read leading to uninitialized memory exposure↗2020-05-16 ▶ DebianCVE-2018-21270: node-stringstream - Versions less than 0.0.6 of the Node.js stringstream module are vulnerable to an...↗2018 ▶